Data Protection Officer (DPO)
Location: East Grinstead
Job type: Permanent
Reporting to: Financial Controller
Line management responsibility: 3 direct reports:
Data Security Compliance Specialist (permanent)
Data Security Compliance Officer (permanent)
Data Security Compliance Advisor (contract)
About the job: The DPO will inform, advise and be the primary point of contact at the Club for data protection, data security and Payment Card Industry Data Security Standard (PCI DSS) compliance.
Serving as a subject matter expert in data protection, the role holder will provide strategic leadership across policy and compliance frameworks. This includes upholding the Club's compliance with UK data protection law and PCI DSS, while ensuring data security policies are closely aligned with established information security standards like ISO 27001\.
Operating under the Data Protection Act 2018 and UK General Data Protection Regulation (UK GDPR), the DPO is engaged in all matters concerning the processing of personal data. As this position is mandated and protected by law, this key role within the Club demands that the post holder executes their duties with integrity, diplomacy and the utmost professionalism. A pragmatic approach is also encouraged.
The DPO heads up the Data Security Compliance Team (DSCT) and manages all team members.
Key Tasks / Accountabilities:
- Serve as statutory DPO under UK data protection law for the Club and Alan Rogers Travel Group, acting as primary liaison for the Information Commission’s Office (ICO), other regulators and data subjects.
- Monitor regulatory change, ICO guidance, legislative updates and technology trends to keep data security policies and operational standards current.
- Own the Privacy Policy suite and maintain privacy governance, including the Master Record of Privacy Statements, Records of Processing Activities (ROPAs), Legitimate Interest Assessments (LIAs) and Data Protection Impact Assessments (DPIAs).
- Act as the final escalation and approval point for data subject requests, law enforcement (and other) disclosures and data protection complaints, ensuring timely and compliant resolution, completed to a high standard.
- Oversee the continued development, implementation and maintenance of data security policies, procedures and standards across the organisation.
- Provide, or oversee the provision of, data protection advice for projects and initiatives, ensuring Privacy by Design is applied and DPIAs are completed where necessary.
- Using the ICO Accountability Tracker, ensure the DSCT monitors data protection compliance, advising and supporting the Club to meet its legal duties, implement proportionate safeguards and protect data subjects' rights.
- Lead, motivate and develop the DSCT team members with personal development plans, career growth support, opportunities and task delegation, and performance management.
- Manage recruitment and onboarding processes for permanent and contract team members, as required.
- Continue to develop a culture of continuous learning and proactive compliance across all departments.
- Provide strategic direction for all data protection and data security training and awareness programs.
- Oversee all data security incident management, directly handling incidents when necessary, and ensure adherence to legal and regulatory reporting timelines. Report breaches to the Club’s Directors, the ICO and/or relevant law enforcement agencies as required.
- Report data security activities, data subject request completion statistics, breach investigations and risk posture to the Directors and members of the Senior Leadership Team (SLT) via the quarterly meeting of the Data Security Protection Group (DSPG).
- Promote an open, 'no\-blame' reporting culture while ensuring corrective solutions and post\-incident improvements are implemented.
- Maintain strategic oversight of PCI DSS compliance, collaborating closely with the Information Systems (IS) Security Specialist, the Club’s acquiring bank and the external Qualified Security Assessor (QSA), as required.
- Ensure IS teams schedule and remediate regular vulnerability and ASV scans, and that penetration tests are carried out annually or when significant change occurs.
- Be responsible for the completion, sign off and submission of annual PCI DSS Self\-Assessment Questionnaires (SAQs) to the Club’s acquiring bank, ensuring evidence of compliance is maintained and documented.
- Ensure all payment channels are PCI DSS compliant and that new channels or changes to existing channels are assessed and appropriate security controls introduced.
- Partner with the Club’s Procurement team and external legal counsel to ensure robust data protection, PCI DSS and data security clauses are embedded in supplier contracts and non\-disclosure agreements.
- Drive privacy and data security requirements developed by the DSCT to be embedded in all relevant projects and initiatives, as well as considered for changes to existing processes.
- Have responsibility for the continued improvement of ‘light touch’ business continuity frameworks, ensuring alignment between data protection requirements, data security policies, IS disaster recovery and business continuity plans.
- Oversee the management and documentation of team representation on Gold and Silver Business Continuity groups.
- Actively push for robust privacy and data security standards by authoring Club\-wide communications and presenting at departmental and team meetings.
- Manage budgets and contractual agreements for third\-party vendors supporting the DSCT’s activities, such as consultants.
- Maintain active membership in key organisational forums, including the Club's Google User Group, AI Governance Board and Cross Functional Board, to maintain continuous awareness of upcoming initiatives, emerging risks and business change.
- Serve as the primary point of contact for the team's third\-party Privacy Management System, tracking updates and ensuring thorough pre\-release testing.
- Act as the Product Owner for the Club's secure email product, overseeing contract management, cost controls and feature rollouts to license holders.
- Attend relevant external industry meetings and conferences to keep knowledge current and stay up to date with legislation, best practice and emerging threats.
Essential skills and experience required:
- Proven track record in a senior data protection, privacy, information security or compliance leadership role, with demonstrable experience of managing and mentoring a team.
- Expert knowledge of UK data protection legislation (e.g. UK GDPR, Data Use and Access Act 2025, DPA 2018, PECR) and ICO guidance.
- Direct experience of liaising with regulatory bodies such as the ICO.
- Solid awareness of ISO 27001 information security best practice and controls.
- One or more recognised professional privacy and/or information security qualifications (e.g. CIPP/E, CIPM, UK GDPR Practitioner, Practitioner Certificate in Data Protection (PC.dp), CISM, CISSP).
- Strong commercial awareness, sound negotiation skills and the ability to influence organisational dynamics at all levels.
- Substantial experience of managing privacy risks associated with complex IT systems, and contract negotiations.
- First rate attention to detail, coupled with an ability to interpret regulations, standards and privacy and security best practice and implement them pragmatically across the Club.
- Exceptional written and verbal communication skills, with proven ability to deliver clear messages and advice under pressure, at all levels and with third parties.
- Quick learner with extremely confident general IT skills, including the use of Google Workspace (Gmail, Drive and Sheets etc.) and/or Microsoft Office (Outlook, Word and Excel etc.)
- Passionate, committed and enthusiastic with a strong desire to drive change.
Desirable skills and experience required:
- Experience of working with or managing corporate business continuity frameworks.
- Hands\-on experience with privacy management platforms, such as OneTrust, working with AI tools and using redaction software such as Adobe Acrobat.
- Awareness of Financial Conduct Authority (FCA) regulations.
Read our Equality and Diversity policy
Policy Statement
The Club is committed to providing equal opportunities in employment and to avoiding unlawful discrimination to its employees and job applicants and when dealing with customers, suppliers or other work\-related contacts or when wearing a work uniform). This policy is intended to assist the Club to put this commitment into practice and compliance with this policy should also ensure that employees do not commit unlawful acts of discrimination. Striving to ensure that the work environment is free of harassment and bullying and that everyone is treated with dignity and respect is an important aspect of ensuring equal opportunities in employment.
It is unlawful to discriminate directly or indirectly in recruitment or employment because of:
Age, Disability, Sex, Gender reassignment, Pregnancy, Maternity, Race (which includes colour, nationality and ethnic or national origins), Sexual orientation, Religion or belief, or because someone is married or in a civil partnership. These are known as Protected Characteristics.
The policy applies to all aspects of employment with the Club, including recruitment, pay and conditions, training, appraisals, promotion, conduct at work, disciplinary and grievance procedures, and termination of employment.
Discrimination after emplo
This listing is from Indeed. View original listing ↗